Oregon Department of Human Services officials confirmed that the organization has suffered a data breach that has exposed personal details and health information of 645,000 clients.
The incident happened in January and the Oregon Department of Human Services is notifying the incident to the clients.
“The Oregon Department of Human Services is notifying about 645,000 clients whose personal information is now at risk from a January data breach. State officials announced the notifications on Tuesday. They‘ll will start mailing them on Wednesday.” states the Statesman-Journal.
“Affected people were enrolled in the department’s welfare and children services programs at the time of the breach. Officials said the compromised data includes personal health information, but it’s unknown if was viewed or inappropriately used.”
Individuals impacted by the data breach were enrolled in the department’s welfare and children services programs at the time of the security incident.
“The state is also providing 12 months of identity theft monitoring and recovery services, which includes a $1 million insurance reimbursement policy to impacted individuals.” reads the Associated Press.
The department was hit by a phishing campaign on January 8, 2019, and at least nine employees have been deceived in the attack.
“The breach happened during an email “phishing” attempt that targeted the department Jan. 8. Nine employees opened the email and clicked on a link that gave the perpetrator access to their email accounts.” concludes the AP.
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – Oregon Department of Human Services, hacking)
[adrotate banner=”5″]
[adrotate banner=”13″]
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best…
Fintech firm Figure confirmed a data breach after hackers used social engineering to trick an…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in BeyondTrust RS and…
A new alleged Russia-linked APT group targeted Ukrainian defense, government, and energy groups, with CANFAIL…
A new threat actor, UAT-9921, uses the modular VoidLink framework to target technology and financial…
Attackers quickly targeted BeyondTrust flaw CVE-2026-1731 after a PoC was released, enabling unauthenticated remote code…
This website uses cookies.